github.com
https://github.com/vogtmh/cmaps CVE-2023-29983
MEDIUM
Companymaps v8.0 - Stored Cross Site Scripting (XSS)
Record summary
CVE-2023-29983 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the admin panel.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBCompanymaps v8.0 - Stored Cross Site Scripting (XSS)ExploitDB exploitby Lucas Noki (0xPrototype)Not analyzed1 file
Repository PoCs
GitHubzPrototype/CVE-2023-29983Repository PoCby zPrototypeStars: 0Not analyzed3 files
References
5github.com
https://github.com/zPrototype/CVE-2023-29983 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-29983 packetstormsecurity.com
https://packetstormsecurity.com/files/172075/CompanyMaps-8.0-Cross-Site-Scripting.html exploit-db.com
https://www.exploit-db.com/exploits/51417